hack that hijacks Firefox' File Not Found Page

User Help for Mozilla Firefox
vizitor
Guest

hack that hijacks Firefox' File Not Found Page

Post by vizitor »

I am seeing a problem in Firefox 1.5.0.3 where the File Not Found Page has been hijacked by a hack. It displays an add for a website (an x site) instead of the page that would normally display when an unknown or incorrect URL is typed into the address bar - if you typed in nytimes.cim for example instead of nytimes.com.

Has anyone else seen this issue and does anyone know how to fix it short of trying a uninstall and clean install?

Thank you,
Much appreciated.
Guest
Guest

Post by Guest »

I doubt it's anything serious. Many servers on the web are configured with Custom 404 pages; even mozillaZine:
http://forums.mozillazine.org/errorpage
vizitor
Posts: 3
Joined: May 6th, 2006, 9:15 am

Post by vizitor »

Indeed, I know of the custom 404 pages when a deep link is not found, but no matter what site it is that is misspelled in the address bar, I get the same page advertising a porn site. It is defintely an infection in my Firefox installation. Mistyping any website yields the same thing, and there is no way all these site would have servers configured with the same 404 advertising some porn site.

I have unsuccessfully done a full text search of the Firefox folder looking for some of the text in the 404 but to no avail. Please let me know of any other suggestions.
User avatar
craigevil
Posts: 3103
Joined: February 20th, 2005, 2:12 pm
Location: OZ
Contact:

Post by craigevil »

What spyware scanners have you tried running?

I would suggest installing and running:
1) Windows Defender
2) Spybot Search and Destroy
3) ewido anti-malware http://www.ewido.net/en/
4) "HijackThis" http://www.spywareinfo.com/~merijn/downloads.html

Also check your HOSTS file too make sure nothing strange is listed there.

Check your Firefox user.js and pref.js files for crap that doesn't belong as well.


Might want to do an online scan for malware also.

There are many sites you can scan for malware.
http://www.ewido.net/en/onlinescan/

A great site to help you along is "If Your PC is Infested w/ Spyware..."
http://www.spywarewarrior.com/rogue_ant ... htm#online
Raspberry PI 400 Distro: Raspberry Pi OS Base: Debian Sid Kernel: 5.15.26-v8+ aarch64 DE: MATE Ram 4GB
Debian - "If you can't apt install something, it isn't useful or doesn't exist"
My Giant Sources.list
Guest
Guest

Post by Guest »

I have the exact same problem. My Firefox 1.5.0.3 is showing a porn page when a standard 404 page should show. The problem doesn't happy in IE, which shows the standard 404 page correctly.
Oscar the Prophet
Posts: 788
Joined: March 12th, 2005, 2:05 pm

Post by Oscar the Prophet »

Look at your address bar. Doe it have a url?
"Life is a struggle, not against sin, not against the Money Power, not against malicious animal magnetism, but against hydrogen ions."
- HL MENCKEN
netfish
Posts: 2
Joined: April 16th, 2006, 5:30 pm

Post by netfish »

Oscar the Prophet wrote:Look at your address bar. Doe it have a url?


There is a url. The url that I want to go but is not found. For example, http://w222.3432.com/, which doesn't exist, will go to that "porn" 404 page.

Below is the source of that page.

=====

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<!-- saved from url=(0038)http://mindcandyemporium DOT com/index.htm -->
<HTML><HEAD><TITLE>AstraDVD dot com - </TITLE>
<META http-equiv=Content-Type content="text/html; charset=windows-1252">
<META http-equiv=KEYWORDS
content="REMOVED">
<META http-equiv=DESCRIPTION
content="REMOVED">
<META
content="REMOVED
<META
content="REMOVED"
name=Description>
</HEAD>
<BODY bgColor=black>
<CENTER>
<TABLE cellSpacing=2 cellPadding=2 align=center border=0>
<TBODY>
<TR>

<TD align=middle width=550 colSpan=3><FONT face=Arial color=white><MAP
name=bc><!-Image map edited by HTML Image Map Editor by Niksa Orlic. Get it at http://www.coma DOT fsb.hr/~norlic/share->
<AREA
onclick=remote=1 shape=RECT coords="21, 5, 488, 299"
href="http://www.asiablue dot com"></MAP><IMG height=300
alt="REMOVED"
src="img/aocentry.jpg" width=500 useMap=#bc border=0></FONT></TD></TR>
<TR>
<TD align=middle colSpan=3><br>
<font color="#FFFFFF"><a href="http://www.asiablue DOT com">
<font color="#FFFFFF" size="4">REMOVED</font></a></font><br>
&nbsp;</TD></TR>
<TR>
<TD></TD>

<TD align=middle width=550><FONT face=arial color=white size=-1>REMOVED
<a href="http://www.asiablue DOT com"><font color="#FFFFFF">
Last edited by DanRaisch on January 9th, 2018, 7:47 pm, edited 1 time in total.
Reason: Objectionable text removed from page source material.
Guest
Guest

Post by Guest »

sound's like a "fake" mp3 in a download p2p or a wmv file...
Guest
Guest

Post by Guest »

also wma file...
netfish
Posts: 2
Joined: April 16th, 2006, 5:30 pm

Post by netfish »

What do you mean by a "fake" mp3 or wmv file? How can you tell from the "source"?
vizitor
Posts: 3
Joined: May 6th, 2006, 9:15 am

Post by vizitor »

Netfish, Oscar, et al., I get the same AstraDVD website coming up whenever I mistype a URL in the address bar. I have used AdBlock to block the images, but I still think this is a harmful infection of systems that we must determine and prevent. Misdirecting (or redirecting) a browser to a different address can be very dangerous indeed, as you can imagine.

Please note that a workaround I have found in the interim is to determine the URL your browser is being redirected to block that address in your firewall. The firewall I use, Sygate Personal Firewall, has logging that showed me the ip address for this shady page and I have blocked it. I know this is a band-aid, or temporary approach to this problem and does not address the core issue, but I suggest it as a stop-gap while a better solution is sought.

One devious thing about this problem is that when a system is so infecgted, any URL typed into the address bar will remain in place and the AstraDVD (or perhaps some other) prom or other shady site will come up and the typed-in URL will actually remain in place in the address bar as if the URL was a real one with an actual IP address, while this is actually not the case.

I am not sure what the Guest who commented above meant by fake mp3, wma, etc., but I think they only meant to further pollute this forum and the web in general with meaningless, and un-collaborative, un-helpful, and scatalogical stuff. Very unfortunate.
Guest
Guest

Post by Guest »

The tojan is basically a buffer overflow exploit. By putting lots of junk in the ID3 tag, it takes advantage of iTunes not checking that the tag falls within proper size limits, so that an undefined state occurs in the program. The rest of the "ID3" tag is then written into memory, where it will cause execution to pass into the rest of the fake mp3 file, causing the virus to run.

There have been similar trojans that hit Windows Media Player and Winamp, they are also patched very quickly, since it is usually a matter of having the player throw out any invalid tags. Once this exploit is patched, attempting to play the file will probably just result in some awful noise to be emitted from the speakers, if anything.
Guest
Guest

Post by Guest »

i know peoples who after downloding an mp3/wma/wmv "fake" file, they got trouble with the browser they use (opening such porn page).
That's why i just suggest the "fake mp3" here.
Or did you put "myserachbar" in your firefox (or any donwload search engin) ?
or a MSN thing for msn...
it can be anything.

ps: i do not want to pollute the forum, but help ;-)
Guest
Guest

Post by Guest »

So is there a fix for the "fake" music files? How can I remove the "porno" page? This only affects Firefox and not IE!
Guest
Guest

Post by Guest »

or affect the default browser...

did you install smiley's from smileycentral?

check the links (the sponsors) "asianblue" is there (contain porn access (sorry)
http://72.14.203.104/search?q=cache:Ckv ... =clnk&cd=2

try grisoft's avg free edition
http://free.grisoft.com
Locked